CVE-2026-19347: itsourcecode Hospital Management System viewdoctor.php sql injection
Published Aug 9, 2026
·Updated
A vulnerability was identified in itsourcecode Hospital Management System 1.0. This issue affects some unknown processing of the file /viewdoctor.php. Such manipulation of the argument delid leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might be used.
Affected Software
1 affected component
itsourcecode Hospital Management System=1.0
Event History
Aug 9, 2026
CVE Published
via MITRE·10:15 AM
Data Sourced
via MITRE·10:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-19347?
CVE-2026-19347 has a medium severity rating of 6.3.
2
How does CVE-2026-19347 affect the Hospital Management System?
CVE-2026-19347 allows for SQL injection through manipulation of the delid argument in the /viewdoctor.php file.
3
Can CVE-2026-19347 be exploited remotely?
Yes, CVE-2026-19347 can be exploited remotely.
4
What is the impact of exploiting CVE-2026-19347?
Exploiting CVE-2026-19347 can lead to unauthorized access to sensitive data through SQL injection.
5
How can I mitigate the risk associated with CVE-2026-19347?
To mitigate the risk of CVE-2026-19347, ensure you validate and sanitize all user inputs, particularly for the delid argument.